7.3 KiB
Executable File
7.3 KiB
Executable File
scuttle — Changelog
v0.4.0 — Verification + Audit Exporters + Signing + Firmware Erase (2026-08-04)
Fourth tagged release. Combines the v0.5 (Verification and Audit) and v0.6 (Firmware Erase) milestones from docs/MANIFEST.md §15.
Added
v0.5 Layer 6 — Extended Verification (scuttle-verify)
- Spot verification (
verify_static_pattern_spot): reads N% of blocks at pseudorandom offsets and compares against the expected pattern. Default 5%. - Block verification (
verify_static_pattern_blocks): reads fixed-size blocks (e.g. 1 MiB) for large devices where sector-by-sector is too slow. - Statistical verification (
compute_statistics,verify_statistical):- Shannon entropy (bits per byte, 0.0–8.0).
- Chi-square statistic for uniform distribution (256 buckets).
- Chi-square p-value (Wilson-Hilferty approximation, 255 degrees of freedom).
- Byte frequency max deviation.
- Failure mapping (
FailedRange): tracks LBA start/end + expected/actual hex for each mismatch. VerifyResultnow carriesfailed_ranges: Vec<FailedRange>andstats: Option<StatisticalResult>.- 5 new unit tests (statistics on zeros, statistics on random, spot verify pass, spot verify mismatch, block verify).
v0.5 Layer 7 — Audit Exporters + Merkle Tree (scuttle-audit)
- XML exporter (
to_xml): well-formed XML with sorted keys, CDATA-escaped text. - CSV exporter (
to_csv): single-row flat format with all key fields. - HTML exporter (
to_html): self-contained HTML page with embedded CSS, styled result (green/red), and a<pre>block with the full JSON. - YAML exporter (
to_yaml): via serde_yaml. - Merkle tree (
MerkleTree): builds a SHA-256 Merkle tree over per-block hashes of the wiped device. Supportsfrom_leavesandfrom_data. Pads to power-of-two. - NIST SP 800-88 compliance report (
ComplianceReport): maps the audit record's NIST class (Clear/Purge/Destroy) to compliance evidence. Serializable to JSON. VerifyResultJsonnow carriesstats: Option<StatisticalResultJson>.- 9 new unit tests (Merkle single/two/three/from_data, XML/CSV/HTML/YAML export, compliance report).
v0.5 Layer 7 — Signing (scuttle-signing)
scuttle-signingcrate: Ed25519 digital signatures for audit records.sign_ed25519(record, key)→SignatureResult(algorithm, signature_hex, key_fingerprint, signed_payload_hash).verify_ed25519_with_key(record, sig, public_key)→bool.load_ed25519_key(path)— load a 32-byte seed from file.generate_ed25519_keypair()— for testing.key_fingerprint(public_key)— SHA-256 of the public key, hex-encoded.SignerBackendtrait +Ed25519Signer,OpenPgpSigner(stub),X509Signer(stub).SignatureJsonfor embedding in the audit record.
- 8 unit tests (sign+verify roundtrip, wrong-key failure, signature changes with record, OpenPGP/X.509 stubs return NotImplemented, signer backend trait, key load rejects wrong length, key load 32 bytes).
v0.6 Layer 9 — Firmware Erase (scuttle-firmware)
scuttle-firmwarecrate: firmware-level sanitization commands.- ATA Secure Erase (
ata_secure_erase,ata_secure_erase_enhanced): viahdparm --security-erase/--security-erase-enhanced. Includesata_detect_secure_eraseandata_set_security_password. - NVMe Sanitize (
nvme_sanitize): supports Block Erase, Crypto Erase, Overwrite actions vianvme-cli. Includesnvme_sanitize_statuspolling (up to 1 hour timeout). - NVMe Format NVM (
nvme_format): format namespace with block size + secure erase setting (None / UserDataErase / CryptographicErase). - SCSI Sanitize (
scsi_sanitize): viasg_sanitize --overwrite. - SCSI Format Unit (
scsi_format): viasg_format --format --six. - TRIM (
trim_discard): directioctl(BLKDISCARD)over the entire device. - FITRIM (
fitrim): directioctl(FITRIM)on a mounted filesystem. - HPA/DCO detect + disable (
detect_hpa_dco,disable_hpa,disable_dco): viahdparm -Nandhdparm --dco-identify/--dco-restore. - High-level dispatch (
run_firmware_erase): takes aPurgeMethod+ device path, runs the right command, returnsFirmwareResult.
- ATA Secure Erase (
- Tools are detected at runtime; if absent, returns
FirmwareError::ToolNotFound. - 8 unit tests (which() finds known binaries, HPA/DCO parse helpers, ATA detect returns gracefully without hdparm).
v0.6 Policy engine integration (scuttle-policy)
WipePlannow carriesfirmware_erase: Option<PurgeMethod>.- SSD policies set
firmware_erase = AtaSecureErase(orAtaSecureEraseEnhancedif supported) for Purge/Enterprise/Forensic/Government/AirGap/Paranoid intents. - NVMe policies set
firmware_erase = NvmeSanitizeCryptofor the same intents. - PMEM policy sets
firmware_erase = PmemCryptoErase(returns Unsupported at runtime since ndctl integration is deferred to v0.7). - HDD / virtual / freespace policies leave
firmware_erase = None. - 5 new tests verify the firmware_erase field is set correctly.
v0.6 Core wipe engine integration (scuttle-core)
JobOptionsnow carriesfirmware_erase: Option<PurgeMethod>.- The wipe engine invokes
scuttle_firmware::run_firmware_eraseBEFORE the overwrite passes. - Firmware erase failures are logged and recorded in
audit.notesbut do NOT abort the wipe — the overwrite passes still run as belt-and-braces.
CLI integration
--certificatenow accepts:none,json,pdf,xml,csv,html,yaml,both(json+pdf),all(all 6 formats).- CLI overrides for
--rounds,--verify,--certificate,--noblankare now correctly re-applied after the policy engine runs (previously the policy engine's profile defaults would overwrite CLI overrides).
Tests
- 105 tests total (was 70 in v0.3):
- 5 new in
scuttle-verify(spot/block/statistical). - 9 new in
scuttle-audit(exporters + Merkle + compliance). - 8 new in
scuttle-signing(Ed25519 sign/verify + stubs). - 8 new in
scuttle-firmware(parse helpers + which). - 5 new in
scuttle-policy(firmware_erase field).
- 5 new in
Known limitations
- Firmware erase requires
hdparm,nvme-cli, andsg3_utilsto be installed. If absent, the function returnsToolNotFoundand the wipe continues with overwrite-only. - PMEM crypto-erase requires
ndctl(deferred to v0.7). - OpenPGP and X.509 signing are stubs (deferred to v2.0).
- The Merkle tree is built but not yet signed or bound into the audit record (the signing happens over the canonical JSON, not the Merkle root — full Merkle-root signing arrives in v0.7).
v0.3.0 — Modern Providers + Profiles/Policies + Freespace Mode (2026-08-04)
See git history for full v0.3.0 changelog. Summary: 5 modern PRNGs (BLAKE3-XOF, XChaCha20, SHAKE128, SHAKE256, Salsa20); Layer 16 benchmark framework; v0.4 modern profile TOML schema with policy_map + constraints; policy engine with 20 built-in policies; 11 modern profiles; --freespace-only mode; fixed MT19937 + ISAAC-64 KAT bugs.
v0.2.0 — Legacy Compatibility (2026-08-04)
See git history. Summary: legacy profiles, legacy flag compatibility, PDF certificate exporter, nwipe symlink support.
v0.1.0 — Architectural Bootstrap (2026-08-04)
See git history. Summary: Layers 1-7 + 13 implemented from scratch in Rust; 24 tests passing.